Arawoof06 opened a new issue, #1232:
URL: https://github.com/apache/arrow-java/issues/1232

   When a query result has endpoints with non-empty locations, 
`ArrowFlightSqlClientHandler.getStreams` clones the connection's `Builder` and 
connects to each advertised location. The clone keeps `username`/`password`, 
`token` and the OAuth config, and encryption is then set from the location 
scheme alone:
   
   ```java
   .withEncryption(endpointUri.getScheme().equals(LocationSchemes.GRPC_TLS))
   ```
   
   So a location with any other scheme (`grpc+tcp://` in particular) turns 
encryption off for that endpoint client even when the connection was opened 
with `useEncryption=true`. `build()` then runs the handshake and sends the 
credentials over the plaintext channel to the advertised host.
   
   The documented meaning of `useEncryption` (default `true`) is "Whether to 
use TLS (the default is an encrypted connection)", so a server-supplied string 
silently overriding it is surprising: a compromised or hostile Flight SQL 
server, or anything able to influence the `FlightInfo` it returns, can have the 
driver hand over the user's credentials in cleartext, and a passive attacker on 
the endpoint path can read them.
   
   Reproduced against a handler built with `withEncryption(true)` plus a 
username/password, given a `FlightInfo` with one endpoint at 
`Location.forGrpcInsecure(...)`: the driver attempts the connection and reaches 
`ClientHandshakeWrapper` on the unencrypted channel instead of refusing it.
   
   `arrow-flight-sql-jdbc-driver`, main.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to